Story
CloudBees Uses Splunk SOAR for Security Telemetry
CloudBees, an information technology organization in the United States, uses Splunk SOAR from Splunk to support detection engineering for detection engineers.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Detection engineers work from the same Splunk SOAR record for security telemetry |
| Risk and compliance | Security telemetry can be reviewed without waiting on a personal export |
| Risk and compliance | Named workflow replaces ad hoc routing for security telemetry |
Story
Inside CloudBees, detection engineering used to depend on whoever still had the latest file. That pattern is common in information technology groups working out of the United States. Detection engineers needed a system that would still make sense after the original project team moved on.
CloudBees uses Splunk SOAR from Splunk as the working layer for security telemetry. Splunk (a Cisco company) is a data platform for security and observability, used to search machine data and investigate incidents. The practical change is simple: detection engineering has a home, and reviews happen there instead of in a forwarded thread.
Nothing in this writeup invents a savings number. What CloudBees gets from Splunk is a durable place to run detection engineering and a way for detection engineers to see the same security telemetry at the same time.